Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Inceptron AB is a Swedish (Lund), EEA-incorporated inference operator with no US parent, and its privacy policy commits to processing Customer Content exclusively within the EU/EEA with zero-retention as the API default — a genuinely favorable sovereignty and retention posture for regulated EU workloads. The composite lands in conditional territory chiefly because two dimensions pull it down: legal exposure is only mid-tier since sub-processors for hosting/infrastructure are described generically rather than named, leaving the serving-chain's EEA-boundedness unverifiable, and security posture is weakened by self-reported (unregistered) ISO 27001 claims, no public status page, and no independently confirmed breach history. Contractual posture is workable but not turnkey — the DPA is available only on request rather than bundled by default, and SCC coverage is referenced but not independently sourced. Serving retention is the strongest dimension, with a documented zero-retention default and bounded (~30-day) telemetry logging when opted in. Given the sound residency and retention story offset by unverified sub-processor chain and unaudited security claims, Stav treats Inceptron as sovereign serving available for EU-regulated workloads, but recommends requesting the named sub-processor list and executed DPA before onboarding as a long-term production vendor.
Privacy policy states Customer Content and API payloads are processed exclusively within the EU/EEA with no transfer outside it, but the unnamed infrastructure sub-processors leave the EEA-boundary of the underlying compute chain unverifiable.
Certifications & legal documents
Inceptron AB is a Swedish, EU-investor-funded entity with no US parent and no CLOUD Act exposure, but generic 'Service Providers / Subprocessors' language for hosting/networking prevents confirming that no US-hyperscaler sub-processor sits in the serving path.
Zero-retention is the documented default for API processing with no logging/storage absent opt-in, and any optional telemetry logging is bounded to roughly 30 days rather than indefinite.
ISO 27001 and GDPR-compliance claims are self-reported with no independent registry confirmation, and there is no public status page or breach-history record to corroborate the stated encryption/access controls.
A GDPR DPA and SCC-based transfer safeguards are contractually referenced but only executed 'if required' on request rather than bundled by default, and no dpa_url or subprocessors_url is published in the Trust Profile.
Risk assessment
Privacy policy discloses only a generic category ("Service Providers / Subprocessors – who provide infrastructure, hosting, and networking") without naming the actual downstream cloud/hosting/network vendors, so customers cannot independently verify the sub-processor chain stays EEA-bound. source ↗
SUBPROCESSINGTerms of Service explicitly disclaim any uptime commitment ("We do not guarantee any specific uptime or response time unless a separate SLA is signed"), which sits in tension with marketing copy elsewhere on the same domain promising "SLA-backed uptime" by default. source ↗
RESILIENCENo public status/incident-history page could be located on inceptron.io, limiting independently verifiable uptime and incident transparency for regulated buyers. source ↗
RESILIENCEInceptron is a small, early-stage company (reported ~20 employees, ~$2.28M raised across seed-stage European investors), which carries ordinary startup financial/organisational stability risk for enterprises relying on it for production regulated workloads. source ↗
GOVERNANCEA GDPR Data Processing Addendum is described as available "if required" on request rather than being a self-serve, always-in-force document, meaning customers must proactively request and execute it. source ↗
CONTRACTUALSafeguards
Privacy policy states Customer Content, including API payloads, is processed exclusively within the EU/EEA and is not transferred outside the EU/EEA, including where retained for opt-in debugging. source ↗
Zero-retention is enabled by default for API processing: prompts and outputs are not logged or stored, with data processed only transiently unless the customer explicitly opts in to logging. source ↗
Where telemetry/logging is used, retention is bounded (telemetry logs typically retained ~30 days) rather than indefinite. source ↗
Inceptron's own site describes its platform as ISO 27001 certified and GDPR-compliant; this is a self-reported claim (no independent registry entry was located during this research). source ↗
Terms of Service commit to encryption in transit/at rest, access controls, and vulnerability management, with a dedicated security contact for issue reporting. source ↗
International-transfer safeguards (SCCs, and DPF-certified recipients where applicable) are contractually referenced for any personal data transferred outside the EEA/UK, and a standard controller-processor DPA can be executed on request. source ↗
Legal entity is clearly identified as Inceptron AB, a Swedish company headquartered in Lund, funded by European investors (42CAP, PROfounders Capital, Ideon Science Park Incubator, Dreamcraft Ventures, LU Ventures), consistent with no US parent/CLOUD Act exposure. source ↗
Privacy-policy issues
Unnamed sub-processors source ↗
The privacy policy references a generic 'Service Providers / Subprocessors' category for infrastructure, hosting, and networking without naming specific vendors, preventing customers from confirming the full chain stays EEA-bound.
DPA not self-serve source ↗
A standard Data Processing Addendum is only executed 'if required' on customer request rather than being automatically bundled with the standard Terms of Service.
Uptime/SLA inconsistency source ↗
Marketing pages advertise 'SLA-backed uptime' while the Terms of Service state no uptime is guaranteed unless a separate SLA is signed, creating ambiguity about default service-level commitments.